Cribl

Security Operations Engineer

United States

Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Information Security, BiotechnologyIndustries

Job Description: Security Operations Engineer

Company Overview

Cribl does things differently. We are a serious company that doesn’t take itself too seriously, and we’re looking for people who love to get stuff done, and laugh a bit along the way. We’re growing rapidly, looking for collaborative, curious, and motivated team members who are passionate about putting customers first. As a remote-first company, we believe in empowering our employees to do their best work, wherever they are.

As the data engine for IT and Security, many of the biggest names in the most demanding industries trust Cribl to solve their most pressing data needs. Ready to do the best work of your career? Join the herd and unlock your opportunity.

Why You’ll Love This Role

The Security Operations Engineer will be a pivotal member of Cribl’s Information Security team, primarily responsible for strengthening our security posture through robust security operations and advanced threat detection. You will lead security incident management, triage, and investigations, and be instrumental in developing innovative solutions to remediate current threats and proactively prevent future attacks. A key aspect of this role will be designing, implementing, and optimizing detection logic to identify sophisticated threats across our environment. You will partner closely with Product Security, IT, and Legal teams, and report to the Chief Information Security Officer.

Responsibilities

As an active member of our team, you will:

  • Monitor security events and alerting via our security tooling, including MSSP, SIEM, AI, and CSPM tooling, to identify and triage potential threats.
  • Develop, implement, and maintain high-fidelity detection rules and alerts within SIEM and other security platforms (e.g., EDR, Cloud Security tools) based on threat intelligence, MITRE ATT&CK framework, and identified risks.
  • Conduct continuous tuning and optimization of existing detection logic to reduce false positives and improve detection efficacy.
  • Respond to issues identified by our Cribl employees.
  • Act as a security incident response lead, including leveraging and improving detection capabilities during investigations.
  • Build, enhance, and manage security playbooks, incorporating detection engineering best practices.
  • Conduct security assessments of corporate assets through vulnerability testing, threat hunts, and purple team activities, with a focus on identifying detection gaps and opportunities.
  • Perform both internal and external security reviews of corporate properties (e.g., the corporate website and enterprise applications).
  • Lead security incident response tabletop exercises.
  • Continue to evolve and champion the use of Cribl products in our security tech stack to enhance detection, analysis, and response capabilities.
  • Collaborate with threat intelligence teams to integrate new indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) into detection strategies.

Requirements

If you’ve got it - we want it:

  • Knowledge of, and experience in, working with modern security principles (e.g., security data lakes, detections as code, EDR, zero trust networking, and other security tooling), as well as demonstrated experience with incident response and management.
  • Proven experience in developing, deploying, and maintaining detection rules (e.g., Sigma, YARA, Splunk SPL, KQL) across various security platforms.
  • Strong understanding of common attack frameworks (e.g., MITRE ATT&CK) and how to map detections to TTPs.
  • Understanding of authentication and authorization schemes such as SAML, OpenID, OAuth2, and SCIM.
  • Experience scripting/coding in at least one of the following languages: Python, NodeJS, Ruby, Bash.
  • Be the go-to technical subject matter expert on security, compliance, and assurance topics.
  • Excellent communication skills and ability to communicate ideas to technical and non-technical audiences.
  • Comfortable with ambiguity, have a strong analytical acumen, self-motivated, able to work cross-functionally.

Skills

Security Operations
Threat Detection
Incident Management
Incident Triage
Incident Investigation
Detection Logic
Security Data Lakes
Detections as Code
EDR
Zero Trust Networking
Sigma
YARA
Splunk SPL
KQL
MITRE ATT&CK
Authentication

Cribl

Data observability solutions for tech businesses

About Cribl

Cribl operates in the data observability market, helping tech businesses monitor, analyze, and visualize their data for better operational and security insights. The company offers two main products: Cribl Stream and Cribl Edge. Cribl Stream enables businesses to efficiently route and transform logs and metrics, either on their own infrastructure or through cloud services, ensuring timely data delivery. Cribl Edge focuses on collecting and processing real-time observability data from edge devices, which can then be sent to Cribl Stream or other destinations. Cribl distinguishes itself by integrating seamlessly with platforms like Office 365 and Microsoft Azure, allowing clients to enhance their data management capabilities. The company's goal is to create effective data ecosystems that empower organizations to make sense of their data.

San Francisco, CaliforniaHeadquarters
2018Year Founded
$576.3MTotal Funding
SERIES_ECompany Stage
Data & Analytics, Enterprise SoftwareIndustries
501-1,000Employees

Benefits

Competitive Salary
Stock Options
Medical, dental, and vision insurance
Flexible spending account (FSA)
401(k) plan offered (US)
Parental Leave
Professional Development and Career Growth
Generous Vacation and Holiday Policy, including 2 Floating Holidays for holidays you observe
Employee Resource Groups that reflect our values driven company culture

Risks

Emerging data observability startups could threaten Cribl's market share with competitive pricing.
Rapid AI advancements may outpace Cribl's offerings if not updated timely.
Economic downturns could impact Cribl's ability to maintain its high valuation.

Differentiation

Cribl offers unique data routing and transformation with Cribl Stream and Cribl Edge.
The company integrates seamlessly with major platforms like Office 365 and Microsoft Azure.
Cribl's focus on real-time data processing sets it apart in the data observability market.

Upsides

Cribl raised $319M in Series E funding, boosting its valuation to $3.5 billion.
The rise of multi-cloud strategies enhances Cribl's integration capabilities across cloud environments.
Increased demand for edge computing solutions positions Cribl Edge for significant growth.

Land your dream remote job 3x faster with AI